CVE-2009-4724

PaymentProcessorScript.net - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2009-4724. PoCs published by MizoZ, ZoRLu.

AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in PPScript by providing crafted URLs that manipulate the 'cid' parameter to extract database information such as user, version, and database name.

Description

SQL injection vulnerability in shop.htm in PaymentProcessorScript.net PPScript allows remote attackers to execute arbitrary SQL commands via the cid parameter.

Exploits (2)

exploitdb WORKING POC VERIFIED
by MizoZ · textwebappsphp
https://www.exploit-db.com/exploits/34493

This exploit demonstrates an SQL injection vulnerability in PPScript by providing crafted URLs that manipulate the 'cid' parameter to extract database information such as user, version, and database name.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: PPScript (version not specified)
No auth needed
Prerequisites: Access to the vulnerable PPScript application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by ZoRLu · textwebappsphp
https://www.exploit-db.com/exploits/9351

This exploit demonstrates SQL injection vulnerabilities in PaymentProcessorScript.net, allowing attackers to extract database information (user, version, database name) via UNION-based SQLi and perform boolean-based blind SQLi.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: PaymentProcessorScript.net
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9351
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36100

Scores

EPSS 0.0094
EPSS Percentile 56.1%

Details

CWE
CWE-89
Status published
Products (1)
paymentprocessorscript/ppscript
Published Mar 18, 2010
Tracked Since Feb 18, 2026